GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Soatok Dreamseeker (soatok@furry.engineer)

  1. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Saturday, 17-May-2025 11:22:17 JST Soatok Dreamseeker Soatok Dreamseeker

    Years of being around folks in open relationships has rendered me immune to like 99% of drama.

    "What would you do if you had a boyfriend and caught him in bed with another man?" -> "idk, put on a pot of coffee?"

    In conversation about 6 days ago from furry.engineer permalink
  2. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Monday, 05-May-2025 22:49:04 JST Soatok Dreamseeker Soatok Dreamseeker
    • mkj
    • AliCat Tomskit’s Rawrrr Side 🐾

    @mkj @AliCatAD I should add some JavaScript that includes that if the document.referrer includes ycombinator.com in the string

    In conversation about 18 days ago from furry.engineer permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.ycombinator.com
      Y Combinator
      Y Combinator created a new model for funding early stage startups. Twice a year we invest in a large number of startups.
  3. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Monday, 05-May-2025 22:02:46 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to
    • phryk 🏴

    @phryk This is always the funniest and dumbest cycle:

    1. I write something on my furry blog.
    2. Someone else submits it to Hacker news.
    3. Someone complains about the furry art on my furry blog.
    In conversation about 18 days ago from furry.engineer permalink
  4. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Monday, 05-May-2025 21:41:49 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to

    Oops.

    In conversation about 18 days ago from furry.engineer permalink

    Attachments


    1. https://furry.engineer/system/media_attachments/files/114/452/267/628/064/641/original/6e3219a38413a2a0.png
  5. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Monday, 05-May-2025 21:41:48 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to

    Hacker News and its vaunted "meritocracy", folks:

    In conversation about 18 days ago from furry.engineer permalink

    Attachments


    1. https://furry.engineer/system/media_attachments/files/114/454/803/780/132/280/original/e6ca3324015ac659.png
  6. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Monday, 05-May-2025 08:38:35 JST Soatok Dreamseeker Soatok Dreamseeker

    (Before anyone complains about the goatse with incorrect numbers of fingers: The other obvious parody of OpenAI's logo is a hate symbol and I didn't want to go with that.)

    In conversation about 18 days ago from furry.engineer permalink
  7. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Monday, 05-May-2025 08:38:28 JST Soatok Dreamseeker Soatok Dreamseeker

    Tech Companies Apparently Do Not Understand Why We Dislike AI

    It's becoming increasingly apparent that one of the reasons why tech companies are so enthusiastic about shoving AI into every product and service is that they fundamentally do not understand why people dislike AI. I will elaborate. I was recently made aware of the Jetbrains developer ecosystem survey, which included a lot of questions about AI. After I answered some of them negatively (and possibly…

    http://soatok.blog/2025/05/04/tech-companies-apparently-do-not-understand-why-we-dislike-ai/

    In conversation about 18 days ago from furry.engineer permalink
  8. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Tuesday, 29-Apr-2025 15:46:07 JST Soatok Dreamseeker Soatok Dreamseeker

    It would be a real shame if thousands of people submitted totally legitimate incidents concerning Texas public schools for these Republican losers to sift through.

    https://defendinged.org/join-the-movement/report-an-incident/

    Context: https://ghostarchive.org/archive/XLPho || https://archive.ph/pIZy5

    Whatever you do, do not crapflood them, troll them, or satirize them.

    In conversation about a month ago from furry.engineer permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      School Administrative Unit 70 has "Furry Crafts Club" for students who identify as furries - Defending Education | Ghostarchive

  9. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 25-Apr-2025 04:17:58 JST Soatok Dreamseeker Soatok Dreamseeker

    Choose cryptography, where you can have to explain tautology like "the empty string is the prefix to every string" to computer science majors that don't understand domain separation.

    In conversation about a month ago from furry.engineer permalink
  10. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Tuesday, 22-Apr-2025 21:29:29 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to
    • Peter Bindels

    @dascandy If I were a betting dhole, I'd put my money on "law enforcement"

    In conversation about a month ago from furry.engineer permalink
  11. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Tuesday, 22-Apr-2025 21:29:27 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to
    • Peter Bindels

    @dascandy Another prospect that was raised: "developed by AI"

    In conversation about a month ago from furry.engineer permalink
  12. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Tuesday, 22-Apr-2025 21:27:33 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to

    None of this is particularly interesting. Lots of people ship god awful cryptography.

    The really interesting thing is how they try to market this pile of shit.

    In conversation about a month ago from furry.engineer permalink

    Attachments


    1. https://furry.engineer/system/media_attachments/files/114/381/224/797/659/517/original/4d0af8f7f6d63499.png
  13. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Tuesday, 22-Apr-2025 21:27:32 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to

    I'm not going to bother digging further to see how keys are managed.

    For all I know, the cipher mode is smoke and mirrors and everyone is using the same hard-coded AES key somewhere to encrypt their chats.

    Don't use xPal.

    When you consider how it's marketed, the features they emphasize, the fact that it's not open source, and the low quality review they're trying to pass off as an "audit", this thing is either a textbook example of developer hubris or it's another law enforcement sting operation.

    In conversation about a month ago from furry.engineer permalink
  14. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Tuesday, 22-Apr-2025 21:27:32 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to

    Their vaunted "cyber security audit" from Dekra is just a checklist exercise against the OWASP Top 10.

    In conversation about a month ago from furry.engineer permalink

    Attachments


    1. https://furry.engineer/system/media_attachments/files/114/381/230/209/241/864/original/9d65c3072709f304.png

    2. https://furry.engineer/system/media_attachments/files/114/381/232/272/833/794/original/13fedb08537dd6f3.png

    3. https://furry.engineer/system/media_attachments/files/114/381/234/566/896/826/original/6ea9cebbcccea913.png
  15. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Tuesday, 22-Apr-2025 21:27:15 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to

    So, right off the bat: "Military-Grade AES-256 Encryption" is a red flag. Nobody in the privacy or security space sees "military-grade" as a good thing.

    If you scroll through their feature list, you'll notice a few things:

    1. It's not open source.
    2. Decoy PINs that expose a second, innocuous profile
    3. Optional feature: Entering your PIN backwards nukes your account
    4. An unhealthy emphasis on message erasure--including on other peoples' devices

    This sounds very familiar, doesn't it?

    This is basically a clone of EncroChat!

    In conversation about a month ago from furry.engineer permalink
  16. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Tuesday, 22-Apr-2025 21:27:14 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to

    Since it's all React.JS, I did the lazy thing: Looked in the assets directory for JavaScript files.

    Success: assets/threads/Threads/encrypt.bundle and assets/threads/Threads/decrypt.bundle.

    Unfortunately, this is just crypto-browserify and some other React libraries webpacked together.

    It's full of side-channels and it's not clear which components are relevant.

    Like, their ghash implementation (used by AES-GCM, which their decrypter uses) uses the && operation after comparing each bit of the state against 0, which short-circuits the right hand side. This introduces a timing side-channel that loudly exposes the entire GHASH state at any given point of time.

    They also implemented AES with S-boxes in pure JavaScript (no bitslicing), which adds a cache-timing leak. Yay.

    Their PKCS7 padding removal step for AES-CBC (which appears to be used for key-wrapping) also maximizes the timing leakage.

    Suffice to say, the only cryptographic primitives I can find in their app are not recommended.

    In conversation about a month ago from furry.engineer permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      http://together.It/
  17. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Tuesday, 22-Apr-2025 21:27:14 JST Soatok Dreamseeker Soatok Dreamseeker
    in reply to

    Earlier, when I thought I had enough motivation to blog about it, I decided to reverse engineer their APK.

    It turns out, there's no actual cryptography code in the .dex files. (p5 and t5 only contained file extension metadata.)

    There's a lot of React code, though.

    In conversation about a month ago from furry.engineer permalink

    Attachments


    1. https://furry.engineer/system/media_attachments/files/114/381/208/634/259/309/original/faf022ea5fcd60b2.png

    2. https://furry.engineer/system/media_attachments/files/114/381/208/906/790/586/original/a51467003b85d2d3.png

  18. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Tuesday, 22-Apr-2025 21:26:36 JST Soatok Dreamseeker Soatok Dreamseeker

    Let's talk about xPal, which purports to be an encrypted messaging app. https://xpal.com

    Anyone that reads my blog probably already knows where this is going.

    If this post accidentally reaches escape velocity and people that don't know me find it: Hi, I'm a furry cryptography nerd. Usually when I talk about so-called private apps, it's to disclose vulnerabilities in them.

    (Today, I just don't have the damn energy to do a formal write-up.)

    Let's start with how they market their app.

    In conversation about a month ago from furry.engineer permalink

    Attachments


    1. https://furry.engineer/system/media_attachments/files/114/381/131/435/204/339/original/8c4f7a2a89e9e792.png

  19. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 18-Apr-2025 22:25:29 JST Soatok Dreamseeker Soatok Dreamseeker
    • Ján Trenčanský

    @j91321 https://www.youtube.com/watch?v=rRbY3TMUcgQ came to my mind when I saw the headline

    In conversation about a month ago from furry.engineer permalink

    Attachments

    1. Erlang The Movie II: The Sequel
      from gar1t
      Erlang's creators discuss the aging language and meet a surprise helper.For anyone having trouble with the dialog, here's a complete transcript:http://www.ga...
  20. Embed this notice
    Soatok Dreamseeker (soatok@furry.engineer)'s status on Friday, 11-Apr-2025 11:05:43 JST Soatok Dreamseeker Soatok Dreamseeker

    Just remember: as annoying as some fedi users are, so many people are worse.

    In conversation about a month ago from furry.engineer permalink
  • Before

User actions

    Soatok Dreamseeker

    Soatok Dreamseeker

    He/him. Gay/demi dhole (Cuon Alpinus)Blogger, programmer, security engineer, cryptography nerd. 30+Too spicy for Twitter (banned with all the prominent journalists on 2022-12-16)I don't represent any company, individual, or community.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          34725
          Member since
          21 Nov 2022
          Notices
          200
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.